Is ChatGPT HIPAA Compliant?
The short answer is no, not the version your staff is using. Here is the tier-by-tier reality and what it takes to use AI with PHI safely.
The Verdict: Is ChatGPT HIPAA Compliant?
Is ChatGPT HIPAA compliant? Yes, with conditions. OpenAI signs a BAA on sales-managed Enterprise and Edu, ChatGPT for Healthcare, the API, and an individual in-product BAA for verified clinicians.
Free, Plus, Pro, Team, and self-serve Business all lack a BAA, and OpenAI trains its models on consumer conversations by default. On those tiers, never for PHI.
ChatGPT for Clinicians covers the individual clinician only; an organization needs ChatGPT for Healthcare.
Verified against OpenAI's published BAA and product pages, July 2026.
| Tier | BAA available | Trains on your data | Verdict for PHI |
|---|---|---|---|
| ChatGPT Free / Plus / Pro | No | Yes, by default (opt-out exists) | Never |
| ChatGPT Team / self-serve Business | No (excluded per OpenAI's BAA article) | No | Never, until OpenAI changes eligibility |
| ChatGPT for Clinicians (free, verified US clinicians: MD/DO, NP, PA, pharmacists) | Yes: individual in-product BAA flow | Confirm in product terms | Individual coverage only; organizations need ChatGPT for Healthcare |
| ChatGPT Enterprise / Edu (sales-managed) and ChatGPT for Healthcare | Yes | No | Possible, with controls in place |
| OpenAI API | Yes; no enterprise agreement required; zero-retention-eligible endpoints, case-by-case | No | Possible, for vetted applications |
This is not legal advice, and your counsel makes the call for your organization.
It Can Be Done. Is Your Organization Doing It?
OpenAI's healthcare offering, ChatGPT for Healthcare, launched January 2026 and is rolling out at named institutions including AdventHealth, Cedars-Sinai, HCA, and Stanford Medicine Children's Health, with BAA support, audit logs, and customer-managed encryption keys. That answers "can it be done." It does not answer "is your organization doing it."
During the New York Times copyright litigation, a 2025 federal court order required OpenAI to preserve consumer ChatGPT conversations, including chats users had deleted. OpenAI's obligations under that order ended September 26, 2025, but conversations preserved during the window stay preserved, and enterprise tiers were exempt throughout. The durable lesson is that consumer-tier prompts sit on infrastructure your organization does not control, subject to legal processes nobody will notify you about.
For how HIPAA rules apply to AI tools generally, see the full HIPAA and AI compliance breakdown.
A BAA Is Not a Compliance Program
Five gaps that exist under every BAA, until you close them. Closing them is what a 90-day governance path is built to do.
Access control
HIPAA requires knowing who used the tool and limiting PHI access to those who need it. A shared Enterprise login fails this on day one.
Audit trails
When OCR asks what happened, you need a record of every prompt that touched PHI. ChatGPT's admin console was not built to be your audit system.
Minimum necessary
Staff need training on what belongs in a prompt at all, even under a BAA.
Policy
An enforceable acceptable use policy that names approved tools and banned ones. Most organizations discover they have neither.
The multi-model problem
A ChatGPT BAA covers ChatGPT. Your staff also use Claude, Gemini, and a dozen note-taking tools. Governing one tool leaves the rest ungoverned.
Your Staff Did Not Wait
Your staff are not waiting for the compliance review. Samsung's engineers leaked source code to ChatGPT three times in twenty days, and healthcare runs the same pattern with higher stakes.
78% of healthcare workers use AI without IT approval, most of it through personal accounts no compliance program has reviewed. The question is not whether ChatGPT can be made compliant. It is whether your organization governs the AI use already happening.
Neither number arrives through procurement. It arrives as a browser tab opened at the end of a shift, on the tier with no BAA and a training default nobody thought to change. Knowing which tier your organization licensed answers half of this. The half a tier table has no row for is AI use that skipped the review.
ChatGPT and HIPAA: Common Questions
Does OpenAI sign a BAA?
Yes, with conditions. Five paths carry one: sales-managed Enterprise, Edu, ChatGPT for Healthcare, the API, and the individual in-product BAA for verified clinicians. ChatGPT Business is explicitly not BAA-eligible. Confirm scope in your contract before any PHI.
Is ChatGPT Plus HIPAA compliant?
No. No BAA is available on Plus, and consumer conversations can be used for training. The subscription price does not change the compliance status.
Is ChatGPT Enterprise HIPAA compliant?
It can support a compliant deployment. BAA, no training on your data, admin controls. Whether your use of it is compliant depends on your access controls, audit trail, training, and policy.
Can doctors use ChatGPT for clinical notes?
Not on consumer tiers with real patient information. With an enterprise agreement, governance controls, and de-identification where required, AI-assisted documentation is achievable. Purpose-built, BAA-covered tools are usually the better fit for clinical documentation.
What if staff already pasted PHI into ChatGPT?
Treat it as a potential breach. Assess what was disclosed, to which account tier, and whether the four-factor breach risk assessment requires notification. Then fix the governance gap that made it possible, because it will happen again.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Reading
AI Tool HIPAA Compliance Directory
BAAs, training policies, and verdicts for the AI tools your staff actually use, in one place.
Read article →Is Claude HIPAA Compliant?
What Anthropic's BAA covers, what it excludes, and where PHI still leaks.
Read article →Is Gemini HIPAA Compliant?
Google's consumer, Workspace, and Vertex AI postures are three different answers.
Read article →Get the Policy Before the Incident
The fastest first step is an acceptable use policy your staff can actually follow. Generate a healthcare-ready draft in minutes, then talk to us about governing the tools your teams already use.